A hacker group that has been in operation since 2011 has been hitting government, military and telecoms organisations with a selection of Windows and Mac OS X attacks, according to a report from a security company.
The “Icefog” hacker collective have been using a backdoor for both operating systems, which has been used to carry out actions on victims’ machines, rather than automatically siphon off data. Attacks started with spear phishing emails, containing attachments with exploit code for a bunch of known vulnerabilities, affecting Microsoft Office, Oracle Java and a range of other software.
Most victims were based in Japan and South Korea. The Japanese House of Representatives and House of Councillors were both targeted. Defence industry contractors Lig Nex1 and Selectron Industrial, shipbuilding companies DSME Tech and Hanjin Heavy Industries, telecom operator Korea Telecom, and media companies Fuji TV and the Japan-China Economic Association were all hit too.
The perpetrators are believed to have bases in China, Japan and South Korea.
Kaspersky said the Mac malware had infected a few hundred machines globally in 2012 after links to it were posed across Chinese bulletin boards. “We believe this could have been a beta-testing phase for Mac OS X versions to be used in targeted attacks later,” the Russian security firm said.
The attackers used a novel attack infrastructure. “Perhaps one of the most important aspects of the Icefog C&Cs is the ‘hit and run’ nature,” Kaspersky’s report read.
“The attackers would set up a C&C, create a malware sample that uses it, attack the victim, infect it, and communicate with the victim machine before moving on. The shared hosting would expire in a month or two and the C&C disappears.
“The nature of the attacks was also very focused – in many cases, the attackers already knew what they were looking for. The filenames were quickly identified, archived, transferred to the C&C and then the victim was abandoned.”
How much do you know about information security? Try our quiz and find out!
Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…
Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…
Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…
Welcome to Silicon In Focus Podcast: Tech in 2025! Join Steven Webb, UK Chief Technology…
European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…
San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…